How unit 4 is examined
This unit covers cloud security, migration, virtualization threats, trust, disaster recovery and lock-in; every asked topic is a 7-mark explain question, and four topics are unasked so far.
Secure Execution Environments and Communications in cloud
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Cloud security is the set of policies, controls and technologies that protect the data, applications and infrastructure of a cloud, and the communication between users and the cloud, from unauthorised access, leakage and attack.</mark>
Key points.
- Authentication proves who the user is, using passwords, multi-factor authentication or tokens before any resource is used.
- Access control (authorisation) gives each user only the permissions the role needs, following the principle of least privilege.
- Encryption protects data at rest (encrypted disks and storage) and data in transit (TLS/SSL, VPN), so intercepted data is unreadable.
- Isolation keeps each tenant's VMs, storage and network separate, so one customer cannot see another's data.
- Logging, monitoring and firewalls detect and block attacks and give an audit trail.
Example. AWS IAM defines users, roles and policies for access control, and S3 buckets with server-side encryption keep stored objects encrypted, with HTTPS protecting them in transit.
Asked: [7 marks] (Dec 2024) Define the security features in the cloud. Illustrate with the help of example.
General Issues and Challenges while migrating to Cloud
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Cloud migration is the process of moving applications, data and other business workloads from on-premises servers to a cloud environment.</mark>
Key points.
- Types of migration: rehost (lift and shift without change), replatform (small optimisations), refactor (redesign for cloud) and retire or replace.
- Cost benefit: pay-as-you-go pricing replaces capital spending on hardware.
- Scalability and flexibility: resources grow or shrink with demand, so peaks are handled without buying servers.
- Disaster recovery and availability: providers replicate data across regions, so recovery is faster and cheaper.
- Security and access: providers give strong physical and network security, and staff can reach services from anywhere.
- Challenges while migrating: downtime, data transfer time, legacy application incompatibility, security and compliance worries, and vendor lock-in.
Asked: [7 marks] (Dec 2024) What is cloud migration? Discuss the benefits of migrating to the cloud.
The Seven-step model of migration into a cloud
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>The seven-step model is a structured, iterative approach that moves an existing application to the cloud by assessing it, separating it from its environment, re-architecting it, and then testing and optimising it.</mark>
<figure class="ds-fig" style="margin:1.4rem 0;overflow-x:auto"><svg xmlns="http://www.w3.org/2000/svg" id="dsfig-u4-01" viewBox="0 0 596 80" width="596" height="80" role="img" aria-label="Seven steps: 1 Assess, 2 Isolate dependencies, 3 Map, 4 Re-architect, 5 Leverage cloud, 6 Test, 7 Optimise"><style>#dsfig-u4-01 .e{stroke:#454C5A;stroke-width:1.4;fill:none}#dsfig-u4-01 .e.hi{stroke:#2340B8;stroke-width:2.6}#dsfig-u4-01 .n{fill:#FFFFFF;stroke:#16181D;stroke-width:1.4}#dsfig-u4-01 .n.hi{fill:#E3E9FC;stroke:#2340B8;stroke-width:2.2}#dsfig-u4-01 .n.rb-b{fill:#16181D;stroke:#16181D}#dsfig-u4-01 .n.rb-r{fill:#BD3227;stroke:#BD3227}#dsfig-u4-01 text{font-family:"JetBrains Mono",ui-monospace,Menlo,Consolas,monospace;font-size:13px}#dsfig-u4-01 .t{fill:#16181D;font-weight:500}#dsfig-u4-01 .t.inv{fill:#FFFFFF;font-weight:700}#dsfig-u4-01 .kd{stroke:#16181D;stroke-width:1.2}#dsfig-u4-01 .dot{fill:#16181D}#dsfig-u4-01 .ann{fill:#2340B8;font-size:11px;font-weight:700}#dsfig-u4-01 .lbl{fill:#6F7787;font-family:system-ui,-apple-system,sans-serif;font-size:12px;font-weight:700}#dsfig-u4-01 .ptr{fill:#2340B8;font-size:12px;font-weight:700}#dsfig-u4-01 .ah{fill:#454C5A}#dsfig-u4-01 .ah.hi{fill:#2340B8}#dsfig-u4-01 .wl rect{fill:#FFFFFF;stroke:#DCE0E7}#dsfig-u4-01 .wl .t{font-size:12px;font-weight:700}#dsfig-u4-01 .wl.hi rect{fill:#2340B8;stroke:#2340B8}#dsfig-u4-01 .wl.hi .t{fill:#FFFFFF}html.dark #dsfig-u4-01 .e{stroke:#B1B7C3}html.dark #dsfig-u4-01 .e.hi{stroke:#8FA3FF}html.dark #dsfig-u4-01 .n{fill:#161920;stroke:#E6E8ED}html.dark #dsfig-u4-01 .n.hi{fill:#1E2748;stroke:#8FA3FF}html.dark #dsfig-u4-01 .n.rb-b{fill:#E6E8ED;stroke:#E6E8ED}html.dark #dsfig-u4-01 .n.rb-r{fill:#FF7E71;stroke:#FF7E71}html.dark #dsfig-u4-01 .t{fill:#E6E8ED}html.dark #dsfig-u4-01 .t.inv{fill:#0F1115}html.dark #dsfig-u4-01 .kd{stroke:#E6E8ED}html.dark #dsfig-u4-01 .dot{fill:#E6E8ED}html.dark #dsfig-u4-01 .ann{fill:#8FA3FF}html.dark #dsfig-u4-01 .lbl{fill:#858D9C}html.dark #dsfig-u4-01 .ptr{fill:#8FA3FF}html.dark #dsfig-u4-01 .ah{fill:#B1B7C3}html.dark #dsfig-u4-01 .ah.hi{fill:#8FA3FF}html.dark #dsfig-u4-01 .wl rect{fill:#161920;stroke:#2A2E37}html.dark #dsfig-u4-01 .wl.hi rect{fill:#8FA3FF;stroke:#8FA3FF}html.dark #dsfig-u4-01 .wl.hi .t{fill:#0F1115}</style><defs><marker id="ah4" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah" d="M0,1 L9,5 L0,9 z"/></marker><marker id="ahh4" viewBox="0 0 10 10" refX="9" refY="5" markerWidth="7" markerHeight="7" orient="auto-start-reverse"><path class="ah hi" d="M0,1 L9,5 L0,9 z"/></marker></defs><path class="e" d="M59,40 L105,40" marker-end="url(#ah4)"/><path class="e" d="M145,40 L191,40" marker-end="url(#ah4)"/><path class="e" d="M231,40 L277,40" marker-end="url(#ah4)"/><path class="e" d="M317,40 L363,40" marker-end="url(#ah4)"/><path class="e" d="M403,40 L449,40" marker-end="url(#ah4)"/><path class="e" d="M489,40 L535,40" marker-end="url(#ah4)"/><circle class="n" cx="40" cy="40" r="18"/><text class="t" x="40" y="40" dy=".35em" text-anchor="middle">S1</text><circle class="n" cx="126" cy="40" r="18"/><text class="t" x="126" y="40" dy=".35em" text-anchor="middle">S2</text><circle class="n" cx="212" cy="40" r="18"/><text class="t" x="212" y="40" dy=".35em" text-anchor="middle">S3</text><circle class="n" cx="298" cy="40" r="18"/><text class="t" x="298" y="40" dy=".35em" text-anchor="middle">S4</text><circle class="n" cx="384" cy="40" r="18"/><text class="t" x="384" y="40" dy=".35em" text-anchor="middle">S5</text><circle class="n" cx="470" cy="40" r="18"/><text class="t" x="470" y="40" dy=".35em" text-anchor="middle">S6</text><circle class="n" cx="556" cy="40" r="18"/><text class="t" x="556" y="40" dy=".35em" text-anchor="middle">S7</text></svg><figcaption style="font-size:.82em;opacity:.72;margin-top:.45rem">Seven steps: 1 Assess, 2 Isolate dependencies, 3 Map, 4 Re-architect, 5 Leverage cloud, 6 Test, 7 Optimise</figcaption></figure>
Key points.
- Assess: study the application, its cost, security and performance needs to decide what should move.
- Isolate the dependencies: separate the application from the on-premises systems, libraries and data it relies on.
- Map the messaging and environment: identify how components communicate and match them to cloud services.
- Re-architect and implement the functionality lost in the move, since some on-premises features do not exist in the cloud.
- Leverage cloud features such as auto-scaling, elastic storage and load balancing.
- Test the migrated application for correctness, performance and security.
- Iterate and optimise: repeat the cycle to cut cost and improve performance.
Asked: [7 marks] (Jun 2025) Explain the seven-step model for migrating applications to the cloud.
Vulnerability assessment tool for cloud
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>A vulnerability assessment tool scans cloud servers, applications and networks to find weaknesses, rank their risk and suggest fixes before attackers exploit them.</mark>
Key points.
- It finds missing patches, open ports, weak configurations and known software flaws.
- Each finding is scored by severity, so the most dangerous are fixed first.
- Scans must be scheduled regularly and after every change, as cloud resources change constantly.
- Examples are Nessus, Qualys, OpenVAS and AWS Inspector; penetration testing is the deeper step that actively exploits the flaws.
Trusted Cloud computing
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Trusted cloud computing is a cloud in which the provider's hardware, software and operations can be verified as secure, so customers can rely on it with their data and applications.</mark>
Key points.
- Trust mechanisms are hardware roots of trust, remote attestation, identity management, encryption and audits.
- A Trusted Platform Module (TPM) is a hardware chip that stores keys and measures the boot state of a server.
- Attestation lets the customer verify that the host runs only approved, unmodified software before placing a VM on it.
- Identity and access management ensures only authorised users and services reach the applications.
- Importance: it protects data, supports legal compliance, and gives tenants the confidence to move sensitive workloads to the cloud.
Asked: [7 marks] (Jun 2025) Explain the importance of trusted cloud computing in securing cloud-based applications.
Virtualization security management-virtual threats
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Virtualization security is the protection of the hypervisor, virtual machines and virtual networks from attacks that exploit the shared physical host.</mark>
Key points.
- VM escape is when malicious code breaks out of a guest VM and reaches the hypervisor or other VMs.
- Hypervisor compromise is the worst risk, since the hypervisor controls every VM on the host.
- Inter-VM attacks use shared memory, cache or virtual networks to spy on a neighbouring VM.
- Snapshots and VM images can leak data or bring back old, unpatched systems.
- Management: harden the hypervisor, isolate VMs and networks, patch regularly, deploy intrusion detection, and secure the VM lifecycle from creation to deletion.
Asked: [7 marks] (Jun 2025) Explain the virtualization security management techniques and the risks associated with VM-based attacks.
VM Security Recommendations and VM-Specific Security techniques
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>VM security recommendations are the practices that harden virtual machines, the hypervisor and their images against attack.</mark>
Key points.
- Harden each guest by removing unused services and ports and applying patches promptly.
- Isolate VMs with separate virtual networks (VLANs) and firewalls, and limit shared resources.
- Protect images and snapshots with encryption and access control, and delete unused ones.
- Install antivirus and host-based intrusion detection in each VM, and monitor logs.
QOS Issues in Cloud
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Quality of Service (QoS) is the level of performance, availability and reliability that the provider promises to the customer, usually written in a Service Level Agreement (SLA).</mark>
Key points.
- QoS parameters are response time, throughput, availability, latency and reliability.
- The SLA fixes targets, such as 99.9 percent uptime, and the penalty if the provider misses them.
- Issues arise from shared resources, noisy neighbours, network delay and sudden load peaks.
- Providers meet QoS with load balancing, auto-scaling and monitoring.
Dependability
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Dependability is the ability of a cloud to deliver its service reliably and to recover quickly from failures, and disaster recovery (DR) is the plan and process that restores systems and data after a disaster.</mark>
Key points.
- Virtual DR replicates VMs and data to another site or region, uses snapshots, and fails over within minutes.
- Physical DR needs a secondary site with duplicate hardware, and recovery is slow and manual.
- RTO (recovery time objective) is how quickly service is restored; RPO (recovery point objective) is how much data loss is acceptable.
| Basis | Virtual DR | Physical DR |
|---|---|---|
| Hardware | Virtual machines on shared infrastructure | Dedicated duplicate servers |
| Cost | Low, pay for use | High, buy and maintain |
| Recovery time (RTO) | Minutes | Hours to days |
| Data loss (RPO) | Near zero with replication | Depends on backup interval |
| Testing | Easy, non-disruptive | Difficult and costly |
| Scalability | Elastic | Fixed capacity |
Asked: [7 marks] (Dec 2024) Explain virtual disaster recovery vs. physical disaster recovery in detail.
Data migration
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Not asked since 2022</span>
Definition. <mark>Data migration is the transfer of data from on-premises storage, or from one cloud to another, into the target cloud storage.</mark>
Key points.
- Methods are online transfer over the network, and offline shipping of storage devices for very large data.
- Data must be encrypted in transit and checked afterwards for integrity.
- Downtime is reduced by first copying the bulk of the data and then syncing only the changes.
- Portability depends on open formats, since proprietary formats make later moves hard.
Challenges and risks in cloud adoption
<span style="display:inline-block;padding:.16em .6em;border:1.5px solid currentColor;border-radius:999px;font-size:.68em;font-weight:700;letter-spacing:.06em;text-transform:uppercase;opacity:.75">Low weight</span>
Definition. <mark>Vendor lock-in is the situation in which a customer depends so much on one provider's proprietary services, APIs and data formats that moving to another provider is costly, slow or impractical.</mark>
Key points.
- Causes are proprietary APIs, closed data formats, provider-specific services and the lack of common standards.
- Implications are high switching cost, less bargaining power, price rises and dependence on the provider's failures.
- Mitigation uses open standards, portable containers, multi-cloud design and exportable data formats.
- Other adoption risks are data security and privacy, loss of control, compliance and downtime.
Asked: [7 marks] (Dec 2024) What do you understand by lock-in property of cloud?
Last-minute revision
- Cloud security features: authentication, access control, encryption, isolation, monitoring.
- Cloud migration means moving applications and data to the cloud; types are rehost, replatform and refactor.
- Seven steps: assess, isolate dependencies, map, re-architect, leverage cloud, test, optimise.
- TPM is a hardware chip; attestation proves a host runs approved software.
- VM escape breaks out of a guest into the hypervisor; hypervisor compromise affects all VMs.
- Inter-VM attacks exploit shared cache, memory or virtual networks.
- RTO is time to restore; RPO is acceptable data loss.
- Virtual DR is cheaper and faster than physical DR.
- Vendor lock-in comes from proprietary APIs and formats; open standards reduce it.
- QoS is promised in an SLA, for example 99.9 percent uptime.
Memory hooks
- Security features: A-A-E-I (Authenticate, Access control, Encrypt, Isolate).
- Seven steps: "A I M R L T O" = Assess, Isolate, Map, Re-architect, Leverage, Test, Optimise.
- VM threats: Escape, Hypervisor, Inter-VM, Snapshot (E-H-I-S).
- RTO is Time, RPO is Point of data loss.
Coverage checklist
- Secure Execution Environments and Communications in cloud: Dec 2024 security features question.
- General Issues and Challenges while migrating to Cloud: Dec 2024 cloud migration question.
- The Seven-step model of migration into a cloud: Jun 2025 seven-step question.
- Vulnerability assessment tool for cloud: no past question.
- Trusted Cloud computing: Jun 2025 trusted cloud question.
- Virtualization security management-virtual threats: Jun 2025 virtualization security question.
- VM Security Recommendations and VM-Specific Security techniques: no past question.
- QOS Issues in Cloud: no past question.
- Dependability: Dec 2024 virtual vs physical DR question.
- Data migration: no past question.
- Challenges and risks in cloud adoption: Dec 2024 lock-in question.